What happens when data is redacted or deleted?
Attachment scanning functionality is part of an early access program. You may see a difference between the information below and your Guard administration experience.
Guard Detects sends an alert when potentially sensitive data is detected. If you determine that the data is sensitive and should not exist in the page or issue, you can choose to redact it, or if it’s within an attachment, delete it. Redact sensitive data from Confluence or Redact sensitive data from Jira
Who can do this? |
データのリダクションによる影響
リダクションを行うと、機密データは削除されて実線に置き換えられます。この実線は、テキストが実際に削除された場所を示しています。実線の長さは機密データの長さとは関係ないため、機密データの復元には使用できません。
You can later edit the page or work item to remove the solid bar if you want to.
The only way to restore redacted content is to use the Guard Detect API, and this must be actioned within 30 days of the redaction.
どの場所のデータがリダクションの対象となるか
検出とリダクションの対象となるのは、次の場所の機密データです。
Confluence page title, page body, and code blocks.
Confluence blog post title, blog post body, and code blocks.
Jira work item fields, history, comments, and code blocks.
次の場所の機密データは検出とリダクションの対象外です。
whiteboards, live pages, or databases
space or project descriptions, sprint names, or other free text areas
text added via some third-party apps or macros
audit log activities that existed before the redaction
履歴のデータに対してリダクションが行われるか?
In Confluence, we only redact sensitive data in the current version of the page. However, you have the option to delete any historical versions that contain the sensitive data from the page history. This completely removes the page versions that contained the data, including any other edits that may have been made in that version, and the record of who contributed to those versions. A new version is added, with a comment to indicate that sensitive data was redacted. Page versions can’t be restored once deleted.
履歴を削除するかどうかは、組織の保存要件によって異なるため、チームと協力して履歴を削除することが適切かどうかを判断することをお勧めします。
選択したインスタンスを編集できますか?
はい、できます。ページに同じ種類の機密データのインスタンスが複数含まれている場合は、それらをすべてを編集することも、選択したインスタンスのみを編集することもできます。
たとえば、3 枚のテスト用クレジット カードと 1 枚の本物のクレジット カードを含む Confluence ページがある場合は、すべてのインスタンスを編集するか、本物のクレジット カードのみを編集して、残りをそのままにしておくかを選択できます。
残りの機密データについては、新しいアラートが生成されます。また、今後誰かがページを更新した場合は、アラートが引き続き生成されます。これを防ぐには、その特定のコンテンツ スキャンの検出ルールからページを除外することをご検討ください。
データが編集されると、ユーザーには何が表示されますか?
アクターには、機密データのリダクションが行われたことを知らせるメールとアプリ内通知が届きます。
ページや作業項目を閲覧または編集する際には、テキストの削除箇所を示す実線が表示されます。これは、そのページや作業項目を閲覧するすべてのユーザーに対して同様に表示されます。
What happens when an attachment is deleted?
When Guard finds an attachment containing sensitive data, you have the option to delete the attachment. This option deletes the attachment and replaces it with a placeholder file in the current version of the page and any historical versions that contained the sensitive attachment. Guard can’t redact sensitive data in an attachment because attachments are files, not editable page content.
You can restore deleted sensitive attachments using the Guard Detect API within 30 days. After 30 days, the file is permanently deleted and cannot be recovered.
Where are attachments deleted?
Attachments containing sensitive data are detected and deleted from:
New uploaded attachments in pages, blog posts, or work items
Is an attachment deleted from the history?
When you delete an attachment from a Confluence page or blog post, it’s deleted from both the current version of the page and any historical versions of the page.
Can I redact only selected parts of an attachment?
An attachment can only be deleted as an entire file. Sensitive attachments support only deletion, and sensitive content in the attachments cannot be redacted individually.
What does the user see when an attachment is deleted?
When you delete an attachment, your users will see a placeholder image indicating that the file was deleted due to presence of sensitive data.
この内容はお役に立ちましたか?